Skyticket Hacked — Over 14 Million Records Possibly Leaked, 5ch: ‘Password Reuse Could Grind Society to a Halt’

From our other sites

The story

Adventure Co., Ltd., which operates the comparison and booking site “skyticket,” announced on October 9, 2026 that unauthorized access to its systems resulted in a leak — or suspected leak — of users’ personal information. The number of potentially affected records is said to exceed 14 million. On 5ch’s News Flash+ forum, posters pointed to the string of recent data breaches at Japanese companies happening around the same time, warned of the danger of secondary damage from reused email addresses and passwords, and voiced frustration with the company’s “apology” response.

“October 9, 2026 — Adventure Co., Ltd.

We have discovered that the system behind our comparison and booking site “skyticket,” which we operate, was subject to unauthorized access by a third party, resulting in the leak — or suspected leak — of our customers’ personal information to outside parties.

We deeply apologize for the significant trouble and concern this has caused our customers and all other parties involved.

Source: news.yahoo.co.jp / Original article here

What people said

11AnonymousOct 9, 2026 15:02
Felt like Japan was the only one getting targeted lately… but yeah, I can kind of guess why.
13AnonymousOct 9, 2026 15:03
For a second I misread that as a 'Skynet' breach.
20AnonymousOct 9, 2026 15:05
Re: #13
He's probably in pretty rough shape too lol
218AnonymousOct 9, 2026 16:10
Re: #13
Sarah Connor's data probably got leaked too, huh
16AnonymousOct 9, 2026 15:03
Good time for other companies to announce their breaches too — it won't stand out now.
28AnonymousOct 9, 2026 15:05
First time I've seen a four-digit number (in units of 10,000) for a leak like this — how many years' worth of garbage data is that?
145AnonymousOct 9, 2026 15:36
Re: #28
Isn't that basically their entire customer base at this point?
31AnonymousOct 9, 2026 15:06
What's going on, leaks are happening like crazy lately… they owe everyone a million yen apiece in apology money.
147AnonymousOct 9, 2026 15:37
Re: #31
Companies that think saying 'we sincerely apologize' makes everything okay
33AnonymousOct 9, 2026 15:06
Wait, so nobody's mentioning that this also makes people targets for 'yami baito' (shady crime gigs that recruit via leaked personal data)?
153AnonymousOct 9, 2026 15:38
Re: #33
Users, tremble and sleep (a common ominous meme phrase)
35AnonymousOct 9, 2026 15:07
With this recent flood of leaks, is Japan basically being hit with cyberwarfare from China or somewhere?
37AnonymousOct 9, 2026 15:07
This is obviously data from wealthy customers,
so it's probably going to be a hot seller on the dark web.
42AnonymousOct 9, 2026 15:09
Re: #37
Rich people wouldn't bother with Skyticket, they'd book direct…
59AnonymousOct 9, 2026 15:12
I got an email from Skyticket, but what am I actually supposed to do about it?
63AnonymousOct 9, 2026 15:13
Re: #59
Do nothing.
64AnonymousOct 9, 2026 15:13
Re: #59
That email itself is the scam.
62AnonymousOct 9, 2026 15:13
It won't turn into a huge fuss unless sites like FANZA or FC2 (Japanese adult-content platforms) get breached.
71AnonymousOct 9, 2026 15:15
Re: #62
Most people using those sites probably already assume their info will leak sooner or later anyway
112AnonymousOct 9, 2026 15:26
Re: #62
Now THAT would be a disaster
117AnonymousOct 9, 2026 15:26
Re: #62
Is there really anyone dumb enough to register for porn sites under their real name?
66AnonymousOct 9, 2026 15:14
At the rate breaches are happening every single day, pretty much everyone in the country is going to have something leaked within a month, and it'll probably get exploited soon after.
75AnonymousOct 9, 2026 15:16
Re: #66
I'm on the list for a few of these companies, but I haven't gotten a single email.
Guess I'm just not affected?
Lawson's notification rate was only about 1 in 10 too
84AnonymousOct 9, 2026 15:18
Re: #66
As for 'abuse,' it's only a matter of time before they start saying 'getting scam emails or phone calls doesn't even count as real abuse!' lol
I can already predict it becoming 'complain once you've suffered actual financial damage! Until then you don't even get a QUO card (gift card)!' lol
67AnonymousOct 9, 2026 15:14
Heads up, phishing emails pretending to be from Rakuten have been on the rise this month too —
the kind that say 'please install the Rakuten account protection app.'
72AnonymousOct 9, 2026 15:15
Re: #67
My inbox is already so clogged with phishing emails it doesn't even function anymore, so I'll be fine
129AnonymousOct 9, 2026 15:29
So who's actually behind this in the end?
North Korea? China?
Or someone else entirely?
132AnonymousOct 9, 2026 15:30
Re: #129
At this point AI is just doing it on its own
133AnonymousOct 9, 2026 15:30
Re: #129
Even high schoolers are hacking with AI these days, so it could honestly be hackers from anywhere in the world
148AnonymousOct 9, 2026 15:37
Feels like capitalist society could actually collapse within a month at this rate

Does the government even realize what's happening?
This might be like January 23, 2020, when the news broke about Wuhan being locked down over COVID
Only a tiny handful of people in Japan have caught on to how bad this is, while the government and the higher-ups have no clue what's going on
189AnonymousOct 9, 2026 15:51
Re: #148
Exactly this

What leaked was email addresses and passwords
Most systems use your email as the login ID
and a lot of people reuse the same password everywhere

So say a hacker group logs into a major retailer like Amazon using those emails and passwords,
and floods it with tens of thousands of fake orders —
that retailer would have to shut down order-taking entirely

Society grinds to a halt

Background and Key Points of This Discussion

Japan’s Act on the Protection of Personal Information requires companies to notify affected individuals and report to the Personal Information Protection Commission when a personal data breach occurs, and this “apology and notice” appears to have been issued in line with that requirement. The thread was dominated by anxiety over the recent string of unauthorized-access disclosures from Japanese companies happening in quick succession, along with warnings about the risk of so-called “credential stuffing” attacks given how many people reuse the same email address and password across multiple services. Some posts speculated about a specific country being behind the attacks, but since no official attribution has been announced, that speculation is treated as baseless and not reflected in the main article text.

*This article is excerpted and summarized from the 5ch (News Flash+) thread “[Apology and Notice] Travel Booking Site “Skyticket” Suffers Unauthorized Access — Over 14 Million Customer Records Possibly Leaked.”

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *